fix(deps): update ai sdk ecosystem (major) - #240
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
renovate
Bot
force-pushed
the
renovate/major-ai-sdk-ecosystem
branch
from
June 27, 2026 22:03
6946bea to
6f20d13
Compare
renovate
Bot
force-pushed
the
renovate/major-ai-sdk-ecosystem
branch
from
June 29, 2026 19:55
6f20d13 to
433a914
Compare
renovate
Bot
force-pushed
the
renovate/major-ai-sdk-ecosystem
branch
from
June 30, 2026 03:54
433a914 to
95c0720
Compare
renovate
Bot
force-pushed
the
renovate/major-ai-sdk-ecosystem
branch
from
June 30, 2026 06:11
95c0720 to
f0c3a1f
Compare
renovate
Bot
force-pushed
the
renovate/major-ai-sdk-ecosystem
branch
from
June 30, 2026 20:34
f0c3a1f to
a10937d
Compare
renovate
Bot
force-pushed
the
renovate/major-ai-sdk-ecosystem
branch
from
July 1, 2026 20:43
a10937d to
3f39365
Compare
renovate
Bot
force-pushed
the
renovate/major-ai-sdk-ecosystem
branch
from
July 2, 2026 03:44
3f39365 to
6c03130
Compare
renovate
Bot
force-pushed
the
renovate/major-ai-sdk-ecosystem
branch
from
July 2, 2026 22:17
6c03130 to
e44e665
Compare
renovate
Bot
force-pushed
the
renovate/major-ai-sdk-ecosystem
branch
from
July 4, 2026 09:03
e44e665 to
083fece
Compare
renovate
Bot
force-pushed
the
renovate/major-ai-sdk-ecosystem
branch
from
July 6, 2026 02:57
083fece to
03fae85
Compare
renovate
Bot
force-pushed
the
renovate/major-ai-sdk-ecosystem
branch
from
July 6, 2026 16:58
03fae85 to
7772ba0
Compare
renovate
Bot
force-pushed
the
renovate/major-ai-sdk-ecosystem
branch
from
July 10, 2026 23:07
84af816 to
5e21306
Compare
renovate
Bot
force-pushed
the
renovate/major-ai-sdk-ecosystem
branch
from
July 11, 2026 21:43
5e21306 to
895318f
Compare
renovate
Bot
force-pushed
the
renovate/major-ai-sdk-ecosystem
branch
from
July 13, 2026 18:51
895318f to
81d0b94
Compare
renovate
Bot
force-pushed
the
renovate/major-ai-sdk-ecosystem
branch
from
July 14, 2026 00:01
81d0b94 to
b8fcdc2
Compare
renovate
Bot
force-pushed
the
renovate/major-ai-sdk-ecosystem
branch
from
July 14, 2026 19:34
b8fcdc2 to
991d763
Compare
renovate
Bot
force-pushed
the
renovate/major-ai-sdk-ecosystem
branch
from
July 14, 2026 22:38
991d763 to
34f390b
Compare
renovate
Bot
force-pushed
the
renovate/major-ai-sdk-ecosystem
branch
from
July 15, 2026 18:53
34f390b to
835ead4
Compare
renovate
Bot
force-pushed
the
renovate/major-ai-sdk-ecosystem
branch
from
July 15, 2026 20:56
835ead4 to
0825c13
Compare
renovate
Bot
force-pushed
the
renovate/major-ai-sdk-ecosystem
branch
from
July 17, 2026 08:41
0825c13 to
1815bec
Compare
renovate
Bot
force-pushed
the
renovate/major-ai-sdk-ecosystem
branch
from
July 17, 2026 13:38
1815bec to
6edb702
Compare
renovate
Bot
force-pushed
the
renovate/major-ai-sdk-ecosystem
branch
from
July 20, 2026 20:11
6edb702 to
694787d
Compare
renovate
Bot
force-pushed
the
renovate/major-ai-sdk-ecosystem
branch
from
July 21, 2026 04:29
694787d to
b249891
Compare
renovate
Bot
force-pushed
the
renovate/major-ai-sdk-ecosystem
branch
from
July 21, 2026 12:51
b249891 to
1db0b1c
Compare
renovate
Bot
force-pushed
the
renovate/major-ai-sdk-ecosystem
branch
from
July 21, 2026 14:13
1db0b1c to
c7188c1
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^3.0.0→^4.0.0^3.0.0→^3.0.0 || ^4.0.0^2.0.0→^3.0.0^2.0.0→^2.0.0 || ^3.0.0^3.0.0→^4.0.0^3.0.0→^3.0.0 || ^4.0.0^3.0.0→^4.0.0^3.0.0→^3.0.0 || ^4.0.0^3.0.0→^4.0.0^3.0.0→^3.0.0 || ^4.0.0^2.0.0→^2.0.0 || ^3.0.0^2.0.0→^3.0.0^3.0.8→^4.0.0^2.0.0→^3.0.0^3.0.0→^3.0.0 || ^4.0.0^3.0.0→^4.0.0^2.3.3→^3.0.0^6.0.138→^7.0.0^6.0.0→^6.0.0 || ^7.0.0Release Notes
vercel/ai (@ai-sdk/anthropic)
v4.0.40Compare Source
Patch Changes
e6087c9]v4.0.39Patch Changes
4579b08: Preserve Anthropic server-tool caller metadata in multi-turn conversations.v4.0.38Patch Changes
7fbfc6d]v4.0.37Compare Source
Patch Changes
401a4ba]v4.0.36Compare Source
Patch Changes
ad6a650]81cd026]v4.0.35Compare Source
Patch Changes
1937bef]v4.0.34Compare Source
Patch Changes
e6415bd: feat(anthropic): add text batch supportv4.0.33Compare Source
Patch Changes
3469d0c]v4.0.32Compare Source
Patch Changes
8b96941: Reject spliced Anthropic generations while allowing duplicate message start events for the active message.v4.0.30Compare Source
Patch Changes
1bec07d]v4.0.29Compare Source
Patch Changes
160ccdb]v4.0.28Compare Source
Patch Changes
9337ecd: Preserve Anthropic prompt-cache matches by replaying complete code-execution transcripts in their original wire shape.79e133c]v4.0.27Compare Source
Patch Changes
5fc7da5]93b2acd]v4.0.26Compare Source
Patch Changes
dc0c28e: Return visible summarized reasoning when generic reasoning enables adaptive thinking.fa95504]v4.0.25Compare Source
Patch Changes
d8210b6: chore: centralize record type guards in provider-utilsb192878: feat: add experimental_toolCaller routing to generateText for code moded8210b6]b192878]v4.0.24Compare Source
Patch Changes
1659cd5]6a5bdff]v4.0.23Compare Source
Patch Changes
0c464d9]c49380c]v4.0.22Compare Source
Patch Changes
1e2f324]v4.0.21Compare Source
Patch Changes
e29788d: fix(anthropic): report thinking tokens as reasoning token usagev4.0.20Compare Source
Patch Changes
cbdc990: feat (provider/anthropic): support fallbacks 'default' mode, which routes safety classifier refusals to Anthropic's recommended fallback model (adds the server-side-fallback-2026-07-01 beta automatically)cbdc990: feat (provider/anthropic): support mid-conversation tool changes via the toolChanges system message provider option, emitting tool_addition/tool_removal content blocks and the mid-conversation-tool-changes-2026-07-01 betacbdc990: feat (provider/anthropic): add claude-opus-5 model id with frontier-tier capabilities (128k output tokens, structured output, adaptive thinking, xhigh effort, sampling parameter rejection, thinking-disabled only at effort high or below)v4.0.19Patch Changes
01a596a: fix (provider/anthropic): use current-generation capability defaults for unrecognized Claude model IDs while retaining conservative defaults for legacy Claude and non-Claude models.v4.0.18Patch Changes
97de198: Warn when an unknown model uses the default 4096 max output token limit.v4.0.17Compare Source
Patch Changes
b72fc7c: fix(amazon-bedrock): sanitize unsupported JSON Schema constraints in native Anthropic structured output9218ebe: fix(provider/anthropic): warn when parallel tool use is requested with JSON tool structured output02ffdcb]76cb673]v4.0.16Compare Source
Patch Changes
afcf19c: fix(provider/anthropic): preserve web search citations when replaying assistant messagescd06458]v4.0.15Compare Source
Patch Changes
31c7be8]v4.0.14Compare Source
Patch Changes
4be62c1: fix(provider-utils): validate provider-response URLs ingetFromApigetFromApinow has avalidateUrlflag. It is optional so existing callers keep compiling (omitting it behaves likefalse, i.e. no validation), but all AI SDK provider packages set it explicitly at every call site so each one makes a visible trust decision. Whentrue, the URL is routed throughfetchWithValidatedRedirects— the same guard used bydownloadBlob— which rejects private/loopback/link-local targets, re-validates every redirect hop, strips proxy/metadata/cookie request headers, and drops all caller headers except the user-agent on cross-origin redirects (custom API-key headers must not follow a redirect off-origin any more thanAuthorizationmay); blocked URLs throwDownloadError. It is enabled at the image/video/audio download and polling call sites where the URL comes from a provider response body; URLs built from developer-configured endpoints passvalidateUrl: falseand are unaffected.A new optional
credentialedOriginwithholds caller headers unless the URL is same-origin with it, so the API key is not sent to a response-supplied host on a different origin.A new optional
trustedOriginexempts URLs (and redirect hops) that are same-origin with the developer-configured provider endpoint from target validation, so self-hosted and localhost deployments whose response URLs point back at the configured host keep working; all other hops are still validated.Also closes range gaps in
validateDownloadUrl(IPv4224.0.0.0/4multicast and the TEST-NET documentation ranges192.0.2.0/24,198.51.100.0/24,203.0.113.0/24; IPv6 documentation ranges2001:db8::/32and3fff::/20), and follows only the fetch-spec redirect status codes (301/302/303/307/308) — aLocationheader on any other status is not followed. This guard performs string/literal checks only and does not resolve DNS; hostnames that resolve to private addresses and DNS rebinding remain out of scope and must be constrained at the network layer (or by injecting a Nodefetchthat pins the resolved IP at connect time) for server deployments handling untrusted URLs. Seecontributing/secure-url-handling.md.cd12954: Reject empty OpenAI, Anthropic, and Replicate base URLs with a helpful AI SDKinvalid argument error.
Updated dependencies [
4be62c1]Updated dependencies [
7805e4a]Updated dependencies [
cd12954]v4.0.12Compare Source
Patch Changes
308a519: chore: enforce consistent imports fromzod/v4instead ofzodv4.0.11Compare Source
Patch Changes
0f93c57]v4.0.10Compare Source
Patch Changes
ac306ed]v4.0.9Compare Source
Patch Changes
2e45d9c: fix(anthropic): wrap invalid tool input in objectv4.0.8Compare Source
Patch Changes
0aa0ff3: fix(anthropic): forwardthinking: { type: 'disabled' }to the API instead of stripping itPreviously, setting
providerOptions.anthropic.thinking = { type: 'disabled' }(or top-levelreasoning: 'none') was accepted by the schema but silently dropped from the outgoing request. For models that default thinking on (e.g. Sonnet 5), this left thinking enabled and could consume a smallmax_tokensbudget entirely. Thedisabledvalue is now sent to the Anthropic Messages API.v4.0.7Compare Source
Patch Changes
5c5c0f5: Add experimental streaming transcription support for transcription models, including OpenAIgpt-realtime-whisperand xAI WebSocket STT.5c5c0f5]v4.0.6Compare Source
Patch Changes
c6f5e62: Prevent prototype pollution when synchronously parsing provider JSON inputs and exposesecureJsonParsefrom provider-utils.679c52a: Normalize a barehttps://api.anthropic.combase URL to include/v1.c6f5e62]v4.0.5Compare Source
Patch Changes
8c616f0]v4.0.4Compare Source
Patch Changes
c18018c: feat (provider/anthropic): addclaude-sonnet-5model idv4.0.3Compare Source
Patch Changes
0274f34]v4.0.2Compare Source
Patch Changes
dfffb27: fix(anthropic): correctly map delta type when code execution tools are usedv4.0.1Compare Source
Patch Changes
6a436e3]v4.0.0Compare Source
Major Changes
832f86f: fix(anthropic): remove cacheCreationInputTokens from providerMetadata34bd95d: feat(ai): add support for uploading provider skills using the provider references abstractionef992f8: Remove CommonJS exports from all packages. All packages are now ESM-only ("type": "module"). Consumers usingrequire()must switch to ESMimportsyntax.c29a26f: feat(provider): add support for provider references and uploading files as supported per provider3887c70: feat(provider): add new top-level reasoning parameter to spec and support it ingenerateTextandstreamText8359612: Start v7 pre-release04e9009: chore: make provider implementations code patterns more consistent, including renaming certain exported symbolsFor all externally exported symbols that were renamed, the old names continue to work via deprecated aliases.
Patch Changes
e02f041: feat(provider/anthropic): add support forclaude-opus-4-8648705c: fix(provider/anthropic): fix remaining errors with Anthropiccode_executiontool dynamic calls from latestweb_fetchorweb_search38fc777: Add AI Gateway hint to provider READMEsee798eb: chore(provider-utils): renameExperimental_SandboxtoExperimental_SandboxSessione748b35: chore: update v3 specs to v419c5ee2: fix(anthropic): reorder assistant content b/w client and provider tool use0ee8aec: feat (provider/anthropic): support passing metadata.user_idc012d57: feat(anthropic): sanitize the unsupported JSON schema validation properties8018480: feat(anthropic): add the new advisor toole5c4f40: Remove staleeffort-2025-11-24beta header — the extended thinking effort parameter is GA and no longer requires the beta flag. Vertex AI's strict validator was actively rejecting requests with this header.f57c702: fix(anthropic): allow both temperature and topP for non-Anthropic models using the Anthropic-compatible APIThe temperature/topP mutual exclusivity check now only applies to known Anthropic models (model IDs starting with
claude-). Non-Anthropic models using the Anthropic-compatible API (e.g. Minimax) can now send both parameters as required by their APIs.2610e84: feat(provider/anthropic): automatically use sandbox in bash toold848405: feat: add optionalabortSignalparameters to sandbox command execution87d1723: chore(anthropic): remove unnecessary messages affix from Anthropic symbols and files9f0e36c: trigger release for all packages after provenance setupacdbf84: Handle errors from anthropic websearch toolad0b376: fix(provider/anthropic): stop addingfine-grained-tool-streaming-2025-05-14beta forclaude-opus-4-758a2ad7: fix: more precise default message for tool execution denial21d1ee3: fix(anthropic): skip passing beta header for tool search tools1fe058b: fix(anthropic): preserve the error code returned by model7fc6bd6: Raise minimum supported Node.js version to 22. Supported versions: 22, 24, and 26.09bd27b: feat (provider/anthropic): add support for inference_geo provider option0c4c275: trigger initial canary release6fd51c0: fix(provider): preserve error type prefix in getErrorMessagee311194: feat(ai): allow passing provider instance touploadFileanduploadSkillas shorthand6c93e36: feat(provider-utils): addspawnCommandmethod toExperimental_Sandboxto allow for detached command execution9bd6512: feat(provider): change file part data property to be tagged with a type and remove the image part type258c093: chore: ensure consistent import handling and avoid import duplicates or cycles5463d0d: feat(provider): align tool result output content file part types with top-level message file part typesb8396f0: trigger initial beta release6b4d325: feat(provider/anthropic): add support forclaude-fable-5and thefallbacksAPI parameterf05a40d: fix(vertex): throw warning when strict: true for vertexAnthropica6617c5: feat(provider-utils): addreadFileandwriteFileplus convenience wrappers toExperimental_Sandboxabstractiona464505: fix(anthropic): propagate toModelOutput providerOption to anthropic tool results90e2d8a: chore: fix unused vars not being flagged by our lint toolingb3976a2: Add workflow serialization support to all provider models.@ai-sdk/provider-utils: NewserializeModel()helper that extracts only serializable properties from a model instance, filtering out functions and objects containing functions. Third-party provider authors can use this to add workflow support to their own models.All providers:
headersis now optional in provider config types. This is non-breaking — existing code that passesheaderscontinues to work. Custom provider implementations that construct model configs manually can now omitheaders, which is useful when models are deserialized from a workflow step boundary where auth is provided separately.All provider model classes now include
WORKFLOW_SERIALIZEandWORKFLOW_DESERIALIZEstatic methods, enabling them to cross workflow step boundaries without serialization errors.0d8f107: feat(provider/anthropic): add support for Opus 4.7 and relevant API enhancementsff5eba1: feat: rollimage-*tool output types into their equivalentfile-*typesv3.0.111Compare Source
Patch Changes
8533108: Preserve Anthropic server-tool caller metadata in multi-turn conversations.31205a4]v3.0.110Compare Source
Patch Changes
b2a4d5a]v3.0.109Compare Source
Patch Changes
2171d15]v3.0.108Compare Source
Patch Changes
dab0a08]v3.0.107Compare Source
Patch Changes
ee2bf30]v3.0.105Compare Source
Patch Changes
0a295e3: Preserve Anthropic prompt-cache matches by replaying complete code-execution transcripts in their original wire shape.v3.0.104Compare Source
Patch Changes
9ecdefe]v3.0.103Compare Source
Patch Changes
7865a71: fix(anthropic): report thinking tokens as reasoning token usagev3.0.102Compare Source
Patch Changes
b4c4426: feat (provider/anthropic): support fallbacks 'default' mode, which routes safety classifier refusals to Anthropic's recommended fallback model (adds the server-side-fallback-2026-07-01 beta automatically)b4c4426: feat (provider/anthropic): support mid-conversation tool changes via the toolChanges system message provider option, emitting tool_addition/tool_removal content blocks and the mid-conversation-tool-changes-2026-07-01 betab4c4426: feat (provider/anthropic): add claude-opus-5 model id with frontier-tier capabilities (128k output tokens, structured output, adaptive thinking, xhigh effort, sampling parameter rejection, thinking-disabled only at effort high or below)v3.0.101Compare Source
Patch Changes
0608dca: fix (provider/anthropic): use current-generation capability defaults for unrecognized Claude model IDs while retaining conservative defaults for legacy Claude and non-Claude models.v3.0.100Compare Source
Patch Changes
b7afc80: Warn when an unknown model uses the default 4096 max output token limit.v3.0.99Compare Source
Patch Changes
db8cff6: fix(amazon-bedrock): sanitize unsupported JSON Schema constraints in native Anthropic structured output94d0f86: fix(provider/anthropic): warn when parallel tool use is requested with JSON tool structured outputv3.0.98Compare Source
Patch Changes
10366a2: fix(provider/anthropic): preserve web search citations when replaying assistant messages19093fd]v3.0.97Compare Source
Patch Changes
06fb54c]v3.0.96Compare Source
v3.0.95Compare Source
v3.0.94Compare Source
Patch Changes
0952964: Prevent prototype pollution when synchronously parsing provider JSON inputs and exposesecureJsonParsefrom provider-utils.764baab: Normalize a barehttps://api.anthropic.combase URL to include/v1.0952964]v3.0.93Compare Source
v3.0.92Compare Source
Patch Changes
ea1e95b]v3.0.91Compare Source
Patch Changes
95bc6fd: feat (provider/anthropic): addclaude-sonnet-5model idfa850e6]v3.0.90Compare Source
Patch Changes
28ff5a7: fix(anthropic): correctly map delta type when code execution tools are usedv3.0.89Compare Source
Patch Changes
b30e43a]v3.0.88Compare Source
Patch Changes
f19334d]v3.0.87Compare Source
Patch Changes
1b40ac7: Publish all packages under the@ai-v6dist tag.1b40ac7]v3.0.86Compare Source
Patch Changes
6086c60: fix(anthropic): reorder assistant content b/w client and provider tool usev3.0.85Compare Source
Patch Changes
779f5cd]v3.0.84Patch Changes
bfa5864]f42aa79]v3.0.82Compare Source
Patch Changes
2a91a17: feat(provider/anthropic): add support forclaude-fable-5and thefallbacksAPI parameterv3.0.81Compare Source
Patch Changes
4084fcd: feat(provider/anthropic): add support forclaude-opus-4-8v3.0.80Compare Source
Patch Changes
263d3e6: fix(provider/anthropic): fix remaining errors with Anthropiccode_executiontool dynamic calls from latestweb_fetchorweb_searchv3.0.79Compare Source
Patch Changes
d61a788: Handle errors from anthropic websearch toolv3.0.78Compare Source
Patch Changes
6e28d25: fix(anthropic): propagate toModelOutput providerOption to anthropic tool resultsv3.0.77Compare Source
Patch Changes
d53314d: feat(anthropic): add the new advisor toolv3.0.76Compare Source
Patch Changes
f591416]v3.0.75Compare Source
Patch Changes
3f06680: Remove staleeffort-2025-11-24beta header — the extended thinking effort parameter is GA and no longer requires the beta flag. Vertex AI's strict validator was actively rejecting requests with this header.v3.0.74Compare Source
Patch Changes
7beadf0]v3.0.73Compare Source
Patch Changes
f8c9ae4: feat(anthropic): sanitize the unsupported JSON schema validation propertiesa727da4: chore: ensure consistent import handling and avoid import duplicates or cyclesa727da4]v3.0.72Compare Source
Patch Changes
a7f3c72: trigger release for all packages after provenance setupa7f3c72]vercel/ai (@ai-sdk/deepseek)
v3.0.29Patch Changes
e6087c9: fix: handle empty string tool callConfiguration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.